Network Device Collaborative Protection Profile with VPN Gateway
ICX 7450 devices support creation of a VPN using the IPsec protocol and also the setup of security associations (SAs) for the IPsec protocol suite. Once the SAs are set up, the IPsec protocol is used to set up and operate encrypted tunnels between two endpoints. NDcPP with VPN gateway allows the FastIron device to be used as a VPN gateway within highly secure and high security federal networks. These networks should be approved by the Commercial Solutions for Classified (CSfC) program.
fips enable
common-criteria command with lines prefixed with "CC". NDcPP with VPN Gateway Requirements
- Management and control traffic, including SSH and HTTPS, should be transported over the IPsec network provided by the FastIron device.
- Elliptic curve-based key establishment support curves.
- The TSF should ensure that all IKE protocols implement DH Groups 14 (2048-bit MODP), 19 (256-bit Random ECP), and 20 (384-bit Random ECP).
- New audit events for IKE and IPsec.
- Support for IKEv2 as defined in RFC 5996.
- Support for AES-256-CBC and AES-128-CBC for IKEv2.
- Support for AES256-GCM and AES-128-GCM for IPsec.
- Support for binary bits-based PSK for IKEv2 authentication.
- Support for X509v3 certificate for authentication of IKEv2 endpoints using ECDSA P-384 and P-256 curves.
- Support for NAT traversal.
- TOE supports IPv4 per RFC 791, IPv6 per RFC 2460, TCP per RFC 793, and UDP per RFC 768.
Note: If the
enable strict-password-enforcement command is enabled, users have up to three login attempts. If a user fails to login
after three attempts, that user is locked out (disabled). Enable the user by entering
the
username name enable command.
NAT Traversal in IKE and IPsec
The evaluated configuration for the VPN Gateway Module requires that IKEv2 and the IPsec tunnel support Network Address Translation (NAT) traversal. The peer device is set up behind a NAT device or a NAT firewall to protect its identity.
IPsec protocol protects the integrity of the IP packet in addition to providing encapsulation and encryption. When an IP packet passes through a NAT device, there is a change in the IP/TCP header leading to an integrity violation that causes the packet to be discarded by the IPsec tunnel end nodes. To overcome this issue, determine whether the IKE peers are capable of supporting NAT traversal or whether there is a NAT device between the IKE peers.
The following commands are introduced as part of NAT traversal in IKE and IPsec:
Selecting the Encryption Algorithm
You select the encryption algorithm for the tunnel when configuring the IPsec proposal.
The following example uses the AES-GCM-128 algorithm for the IPsec proposal named ipsec_proposal. Because the AES-GCM-256 algorithm is used by default, it must be disabled.
device(config)# ipsec proposal ipsec_proposal device(config-ipsec-proposal-ipsec_proposal)# no encryption-algorithm aes-gcm-256 device(config-ipsec-proposal-ipsec_proposal)# encryption-algorithm aes-gcm-128
The following example displays the configuration of an IPsec proposal named ipsec_proposal. AES-GCM-128 is configured as the accepted encryption algorithm.
device# show ipsec proposal ipsec_proposal ================================================================================== Name : ipsec_proposal Protocol : ESP Encryption : aes-gcm-128 Authentication : NULL ESN : Disable Mode : Tunnel Ref Count : 0
Audit Logging
FastIron devices support logging of IKE and PKI transaction details. The logs are automatically generated syslog messages that contain the IKEv2 and PKI transaction details.
There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional IKE or PKI transaction details.